The Kent District Library says the computer system outage that closed all its branches is due to a “ransomware event.”
The district recently discovered the event, but provided…
Weekly intelligence
Trend-first
Weekly ransomware & data leak landscape
A seven-day view of claim activity, leak escalation, actor concentration, sector shifts, and supporting news context from eCrime.ch.
Window: 2026-04-22 → 2026-04-28 UTC
Choose a report date
Observed events
168
Public claims in the selected week
Data leak indicators
30
17.9% of observed events
Active actors
34
Distinct groups with observed activity
Torrent-linked events
0
Events intersecting with torrent intelligence
What changed this week?
•
Qilin generated the highest visible claim volume this week, representing 20.8% of observed events.
•
17.9% of observed events in this window showed a public data-leak indicator, which is a stronger escalation signal than a fresh listing alone.
•
Construction was the most represented sector in this window with 10 observed events.
•
5 actor(s) appeared active this week without matching activity in the prior 30-day lookback, suggesting fresh campaigns, rebrands, or resurfacing infrastructure.
•
85 tracked leak sites were still online as of the report date snapshot, giving useful context on current ecosystem churn and monitoring pressure.
Coverage snapshot
As of 2026-04-28 UTC.
Leak sites observed this week
34
Leak sites online near report date
85
Threat actor profiles updated this week
5
Countries represented this week
37
Sectors represented this week
68
Top active actors
By observed claim volumeQilin
35 events · 6 leak indicators
DragonForce
16 events · 2 leak indicators
Gentlemen
14 events · 0 leak indicators
INC Ransom
13 events · 1 leak indicator
Eraleignews
9 events · 9 leak indicators
LeakedData
9 events · 3 leak indicators
Coinbase Cartel
7 events · 0 leak indicators
LockBit 5.0
7 events · 0 leak indicators
Emerging or resurfacing actors
No matching activity in prior 30 days- M3rx 6 events
- CL0P 1 event
- Meduza Locker 1 event
- Rhysida 1 event
- Trident 1 event
Country mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
United States62
- Qilin13 events · 1 leak indicator
- DragonForce12 events · 1 leak indicator
- INC Ransom9 events · 0 leak indicators
- Akira3 events · 0 leak indicators
- LeakedData3 events · 2 leak indicators
- ShinyHunters3 events · 2 leak indicators
- Payouts King2 events · 0 leak indicators
- World Leaks2 events · 1 leak indicator
Germany8
- LockBit 5.02 events · 0 leak indicators
- Qilin2 events · 1 leak indicator
- Akira1 event · 0 leak indicators
- BravoX1 event · 0 leak indicators
- Gentlemen1 event · 0 leak indicators
- INC Ransom1 event · 1 leak indicator
United Kingdom7
- Qilin3 events · 0 leak indicators
- AiLock1 event · 0 leak indicators
- Brain Cipher1 event · 0 leak indicators
- M3rx1 event · 0 leak indicators
- Trident1 event · 1 leak indicator
Canada6
- Beast1 event · 0 leak indicators
- M3rx1 event · 0 leak indicators
- Payload1 event · 0 leak indicators
- PEAR1 event · 1 leak indicator
- Qilin1 event · 0 leak indicators
- Rhysida1 event · 0 leak indicators
Australia5
- DragonForce1 event · 0 leak indicators
- Gentlemen1 event · 0 leak indicators
- Kairos1 event · 0 leak indicators
- M3rx1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
Italy4
- Qilin2 events · 1 leak indicator
- INC Ransom1 event · 0 leak indicators
- M3rx1 event · 0 leak indicators
Indonesia3
- Eraleignews1 event · 1 leak indicator
- RansomHouse1 event · 0 leak indicators
- World Leaks1 event · 0 leak indicators
Sweden3
- DragonForce1 event · 0 leak indicators
- INC Ransom1 event · 0 leak indicators
- Qilin1 event · 1 leak indicator
Sector mix
Share of weekly events across the last 12 reporting windows. Click to expand top actors for this week.
Construction10
- INC Ransom3 events · 1 leak indicator
- Qilin3 events · 0 leak indicators
- Gentlemen2 events · 0 leak indicators
- Brain Cipher1 event · 0 leak indicators
- PEAR1 event · 0 leak indicators
Law Practice8
- LeakedData3 events · 2 leak indicators
- DragonForce2 events · 2 leak indicators
- CL0P1 event · 0 leak indicators
- INC Ransom1 event · 0 leak indicators
- Payload1 event · 0 leak indicators
Retail7
- DragonForce2 events · 0 leak indicators
- BravoX1 event · 0 leak indicators
- Eraleignews1 event · 1 leak indicator
- INC Ransom1 event · 0 leak indicators
- LockBit 5.01 event · 0 leak indicators
- M3rx1 event · 0 leak indicators
Medical Practice6
- Qilin2 events · 1 leak indicator
- Beast1 event · 0 leak indicators
- Eraleignews1 event · 1 leak indicator
- INC Ransom1 event · 0 leak indicators
- M3rx1 event · 0 leak indicators
Financial Services5
- Anubis2 events · 0 leak indicators
- Qilin2 events · 0 leak indicators
- DragonForce1 event · 0 leak indicators
Hospitals and Health Care5
- Eraleignews1 event · 1 leak indicator
- Gentlemen1 event · 0 leak indicators
- LockBit 5.01 event · 0 leak indicators
- NightSpire1 event · 0 leak indicators
- World Leaks1 event · 1 leak indicator
Software Development5
- Gentlemen2 events · 0 leak indicators
- BlackShrantac1 event · 0 leak indicators
- Qilin1 event · 0 leak indicators
- ShinyHunters1 event · 0 leak indicators
Government Administration4
- Gentlemen1 event · 0 leak indicators
- INC Ransom1 event · 0 leak indicators
- Payload1 event · 0 leak indicators
- Qilin1 event · 0 leak indicators
Organization size bands
Share of weekly events by employee-size group across the last 12 reporting windows.
- 51-200 employees 42
- 11-50 employees 35
- 1,001-5,000 employees 19
- 201-500 employees 12
- 501-1,000 employees 12
- 2-10 employees 10
Notable actor profile updates
Active actor records only.
New ransom note observed
Exitium
2026-04-27 UTC
Adding newly observed ransom note, shared by ESET research. Thank you!
New actor infrastructure / contact channel
No infrastructure/contact-channel change logged in this reporting window.
New vuln / TTP intelligence
No vuln/TTP change logged in this reporting window.
Recent signal samples
Selected weekly signals.
| Actor | Sector | Country | Leak proof | Seen |
|---|---|---|---|---|
| Krybit | Paper and Forest Product Manufacturing | Austria | Claim only | 2026-04-28 |
| CL0P | Law Practice | United States | Claim only | 2026-04-28 |
| INC Ransom | Automation Machinery Manufacturing | United States | Claim only | 2026-04-28 |
| World Leaks | IT Services and IT Consulting | Indonesia | Claim only | 2026-04-28 |
| World Leaks | Wholesale Building Materials | Brazil | Claim only | 2026-04-28 |
| World Leaks | Paper and Forest Product Manufacturing | Mexico | Claim only | 2026-04-28 |
| LockBit 5.0 | Hospitals and Health Care | United States | Claim only | 2026-04-28 |
| LockBit 5.0 | Technology, Information and Internet | Spain | Claim only | 2026-04-28 |
| ShinyHunters | Software Development | United States | Claim only | 2026-04-28 |
| Everest | Data Infrastructure and Analytics | United States | Claim only | 2026-04-28 |
| INC Ransom | Architecture and Planning | United States | Claim only | 2026-04-28 |
| Qilin | Mental Health Care | United States | Claim only | 2026-04-27 |
News and research context
Recent articles from the same time window.
But if you didn’t see a red-flag signal during a scan of the network, you’re not alone: Almost 7,500 organizations around the world were hit by ransomware last year—and there are…
Related actor: M3rx
M3rx is a new ransomware name with a leak site, a Tox contact, and a Windows encryptor that is already doing real work.
. It carries an embedded config, writes RECOVERY_NOTES.T…
Generation Development Group Limited (‘GDG’ or ‘Company’) (ASX: GDG), advises that one of its subsidiary companies, Generation Life Limited, is responding to a contained cyber inc…
ITRON, INC. Cybersecurity Incident
2026-04-24
On April 13, 2026, Itron, Inc. (the “Company” or “Itron”) was notified that an unauthorized third party had gained access to certain of its systems.
The Company activated its c…
Related actor: BlackFile
Unit 42 has responded to numerous incidents since February 2026 involving data theft and extortion across various industries. We attribute a specific portion of this financially-m…
Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security
2026-04-23
The 2026 InsurSec Report from At-Bay, covering more than 100,000 policy years of claims data, documents a 7% year-over-year rise in overall claim frequency and an all-time high av…
Related actor: Kyber
During a March 2026 incident response engagement, Rapid7 recovered two Kyber ransomware payloads deployed in the same environment, one targeting VMware ESXi infrastructure and the…
A private club failed to take all practicable steps to protect the personal data of its members following a ransomware-related data breach that affected more than 9,000 people, th…
Mile Bluff Statement
2026-04-23
Mile Bluff Medical Center in Mauston is currently experiencing system disruptions related to a security event involving data encryption.
Upon detection, Mile Bluff immediately…
Notes
- Observed events reflect monitored leak-site and extortion activity, not independent confirmation of every intrusion.
- Data-leak indicators reflect visible public leak evidence or escalation, which is stronger than a fresh listing alone.
- Country, sector, and company-size metadata can be incomplete. Unknown values are excluded from the public mix views.
- The goal is to explain concentration, escalation, churn, and patterns — not to build a wall of named victims.
Method
- The page uses a fixed seven-day window based on the selected date.
- Only public-facing actor and event records are included.
- Counts and breakdowns are designed for trend review, not incident confirmation.